Polygon Addresses Security Flaws with Hard Forks, No Exploitation Found

Polygon Addresses Security Flaws with Hard Forks, No Exploitation Found

First seen 30 Aug 2026, 02:18 UTC ChaincatcherEn.Bloomingbit 30.1

Article Content

Browse articles
ThreatCluster

Polygon has disclosed multiple security vulnerabilities in its proof-of-stake network, which were addressed through hard forks named Austin and Kyoto. The vulnerabilities affected the Bor and Heimdall clients, posing risks such as denial-of-service (DoS) attacks and validator resource exhaustion. The most critical issue involved the Heimdall client, where a specially crafted transaction could overload validators and disrupt network operations. Polygon confirmed that these vulnerabilities were not exploited on the mainnet and that the fixes were thoroughly tested before public disclosure. Nodes running outdated client versions have been removed from the consensus process and must upgrade to continue participating. The required updates include Bor v2.10.0 and Heimdall v0.11.0, both of which are now active on the mainnet.

Key Points: • Polygon fixed multiple security vulnerabilities in its PoS network through hard forks. • No exploitation of the vulnerabilities was detected on the mainnet. • Affected nodes must upgrade to the latest client versions to rejoin the network.

Timeline

2026-08-29
Polygon discloses vulnerabilities
Polygon revealed multiple security flaws in its network that were fixed through hard forks, with no exploitation detected.
Chaincatcher
2026-08-30
Hard forks activated
The Austin and Kyoto hard forks were activated to address the vulnerabilities, requiring node upgrades to maintain network participation.
En.Bloomingbit